CVE-2002-1395: Low severity Debian Internet Message vulnerability
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1395?
CVE-2002-1395 is classified as a moderate severity vulnerability due to the potential for unauthorized access and file manipulation by local users.
How do I fix CVE-2002-1395?
To fix CVE-2002-1395, update to the latest version of the Internet Message software that resolves the predictable file and directory names issue.
Who is affected by CVE-2002-1395?
CVE-2002-1395 affects users of Internet Message versions 141-0 and 133-0 on Debian systems.
What types of attacks can CVE-2002-1395 enable?
CVE-2002-1395 can enable local attackers to gain unauthorized directory permissions and manipulate files on compromised systems.
Is CVE-2002-1395 still a risk today?
While CVE-2002-1395 was documented in 2002, systems still running the affected versions without updates remain at risk.